Apparently this MChap vulnerability has been around awhile. It's been broken for some time, just wasn't practical to break the hash. What Moxie did was add the ability to bust the hash in the cloud making it faster and easier. In a PPTP situation grabbing that mchap hash enroute is not easily done. The risk is there (always has been) and PPTP users should move away as soon as practical, PPTP is legacy and now less secure than ever. But no need to panic about this one, imho.
Wireless MChap2 folks should make their clients validate the radius server cert before passing the hash. Disclaimer: The above is paraphrasing my source who was at Moxies talk on this at Defcon. ________________________________________ From: Ben Scott [[email protected]] Sent: Tuesday, July 31, 2012 11:51 AM To: NT System Admin Issues Subject: Re: MSCHAP V2 completely broken On Tue, Jul 31, 2012 at 11:40 AM, Matthew W. Ross <[email protected]> wrote: > I don't follow the crypto world, so is there an alternative crypto for PPTP > available? Just curious. It's not so much PPTP as Microsoft's various attempts at authentication/key exchange methods that are broken. But for VPNs, the rest of the world seems to have gone in the direction of IPsec- and SSL-based solutions. OpenVPN is SSL-based, and Win 2000 and later support an IPsec-based VPN. This is prolly more significant for places that are using MS-CHAP for wireless/network authentication. -- Ben ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/> ~ --- To manage subscriptions click here: http://lyris.sunbelt-software.com/read/my_forums/ or send an email to [email protected] with the body: unsubscribe ntsysadmin ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/> ~ --- To manage subscriptions click here: http://lyris.sunbelt-software.com/read/my_forums/ or send an email to [email protected] with the body: unsubscribe ntsysadmin
